Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-44026 KEV |
|
[KEV] SQL Injection in roundcube (CVE-2021-44026)
SQL injection in roundcube (CVE-2021-44026). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-0165 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2016-0165)
vulnerability in Microsoft win32k (CVE-2016-0165). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-34752 |
|
SQL Injection in sqli (CVE-2023-34752)
SQL injection in sqli (CVE-2023-34752). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34944 |
|
Unrestricted File Upload in chamilo (CVE-2023-34944)
vulnerability in chamilo (CVE-2023-34944). Successful exploitation can lead to full system takeover.
|
| CVE-2023-27997 KEV |
|
[KEV] Vulnerability in Fortinet fortios-and-fortiproxy-ssl-vpn (CVE-2023-27997)
vulnerability in Fortinet fortios-and-fortiproxy-ssl-vpn (CVE-2023-27997). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2023-3079 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2023-3079)
vulnerability in Google chromium-v8 (CVE-2023-3079). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-33009 KEV |
|
[KEV] Vulnerability in Zyxel multiple-firewalls (CVE-2023-33009)
vulnerability in Zyxel multiple-firewalls (CVE-2023-33009). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-33010 KEV |
|
[KEV] Vulnerability in Zyxel multiple-firewalls (CVE-2023-33010)
vulnerability in Zyxel multiple-firewalls (CVE-2023-33010). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-29551 |
|
Out-of-Bounds Write in mozilla (CVE-2023-29551)
out-of-bounds write in mozilla (CVE-2023-29551). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29533 |
|
Vulnerability in mozilla (CVE-2023-29533)
vulnerability in mozilla (CVE-2023-29533). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29535 |
|
Vulnerability in mozilla (CVE-2023-29535)
vulnerability in mozilla (CVE-2023-29535). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29536 |
|
Use-After-Free in mozilla (CVE-2023-29536)
vulnerability in mozilla (CVE-2023-29536). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29537 |
|
Vulnerability in mozilla (CVE-2023-29537)
vulnerability in mozilla (CVE-2023-29537). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29538 |
|
Vulnerability in mozilla (CVE-2023-29538)
vulnerability in mozilla (CVE-2023-29538). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29539 |
|
Vulnerability in mozilla (CVE-2023-29539)
vulnerability in mozilla (CVE-2023-29539). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29540 |
|
Open Redirect in mozilla (CVE-2023-29540)
vulnerability in mozilla (CVE-2023-29540). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29541 |
|
Vulnerability in mozilla (CVE-2023-29541)
vulnerability in mozilla (CVE-2023-29541). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29543 |
|
Use-After-Free in mozilla (CVE-2023-29543)
vulnerability in mozilla (CVE-2023-29543). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29544 |
|
Vulnerability in mozilla (CVE-2023-29544)
vulnerability in mozilla (CVE-2023-29544). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29548 |
|
Vulnerability in mozilla (CVE-2023-29548)
vulnerability in mozilla (CVE-2023-29548). Data can be tampered with by attackers.
|
| CVE-2023-29549 |
|
Vulnerability in mozilla (CVE-2023-29549)
vulnerability in mozilla (CVE-2023-29549). Data can be tampered with by attackers.
|
| CVE-2023-29550 |
|
Vulnerability in mozilla (CVE-2023-29550)
vulnerability in mozilla (CVE-2023-29550). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34362 KEV |
|
[KEV] SQL Injection in Progress moveit-transfer (CVE-2023-34362)
SQL injection in Progress moveit-transfer (CVE-2023-34362). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-28771 KEV |
|
[KEV] OS Command Injection in Zyxel multiple-firewalls (CVE-2023-28771)
OS command injection in Zyxel multiple-firewalls (CVE-2023-28771). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-33234 |
|
Vulnerability in apache-airflow-providers-cncf-kubernetes (CVE-2023-33234)
vulnerability in apache-airflow-providers-cncf-kubernetes (CVE-2023-33234). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2023-2868 KEV |
|
[KEV] Vulnerability in Barracuda networks barracuda-networks (CVE-2023-2868)
vulnerability in Barracuda networks barracuda-networks (CVE-2023-2868). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32409 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2023-32409)
vulnerability in Apple multiple-products (CVE-2023-32409). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-28204 KEV |
|
[KEV] Out-of-Bounds Read in Apple multiple-products (CVE-2023-28204)
vulnerability in Apple multiple-products (CVE-2023-28204). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-32373 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2023-32373)
vulnerability in Apple multiple-products (CVE-2023-32373). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2004-1464 KEV |
|
[KEV] Vulnerability in Cisco ios (CVE-2004-1464)
vulnerability in Cisco ios (CVE-2004-1464). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-6415 KEV |
|
[KEV] Information Disclosure in Cisco ios (CVE-2016-6415)
vulnerability in Cisco ios (CVE-2016-6415). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-21492 KEV |
|
[KEV] Vulnerability in Samsung mobile-devices (CVE-2023-21492)
vulnerability in Samsung mobile-devices (CVE-2023-21492). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-47879 |
|
Code Injection in jedox (CVE-2022-47879)
code injection in jedox (CVE-2022-47879). Successful exploitation can lead to full system takeover.
|
| CVE-2022-47880 |
|
Vulnerability in jedox (CVE-2022-47880)
vulnerability in jedox (CVE-2022-47880). Confidential information can be exposed externally.
|
| CVE-2016-8735 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2016-8735)
vulnerability in Apache tomcat (CVE-2016-8735). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2015-5317 KEV |
|
[KEV] Information Disclosure in jenkins (CVE-2015-5317)
vulnerability in jenkins (CVE-2015-5317). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-0196 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2014-0196)
vulnerability in Linux kernel (CVE-2014-0196). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-3904 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2010-3904)
vulnerability in Linux kernel (CVE-2010-3904). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-25717 KEV |
|
[KEV] Code Injection in Ruckus wireless ruckus-wireless (CVE-2023-25717)
code injection in Ruckus wireless ruckus-wireless (CVE-2023-25717). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-3560 KEV |
|
[KEV] Authorization Flaw in Red hat red-hat (CVE-2021-3560)
vulnerability in Red hat red-hat (CVE-2021-3560). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3427 KEV |
|
[KEV] Vulnerability in Oracle java-se-and-jrockit (CVE-2016-3427)
vulnerability in Oracle java-se-and-jrockit (CVE-2016-3427). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-29333 |
|
Microsoft Access Denial of Service Vulnerability
Microsoft Access Denial of Service Vulnerability
|
| CVE-2023-29335 |
|
Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
|
| CVE-2023-29336 KEV |
|
[KEV] Use-After-Free in Microsoft win32k (CVE-2023-29336)
vulnerability in Microsoft win32k (CVE-2023-29336). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-30185 |
|
Unrestricted File Upload in crmeb (CVE-2023-30185)
vulnerability in crmeb (CVE-2023-30185). Successful exploitation can lead to full system takeover.
|
| CVE-2023-30242 |
|
SQL Injection in sqli (CVE-2023-30242)
SQL injection in sqli (CVE-2023-30242). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45046 KEV |
|
[KEV] Vulnerability in Apache log4j2 (CVE-2021-45046)
vulnerability in Apache log4j2 (CVE-2021-45046). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-21839 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2023-21839)
vulnerability in Oracle weblogic-server (CVE-2023-21839). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-1389 KEV |
|
[KEV] Command Injection in Tp-link archer-ax21 (CVE-2023-1389)
command injection in Tp-link archer-ax21 (CVE-2023-1389). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-2206 |
|
SQL Injection in sqli (CVE-2023-2206)
SQL injection in sqli (CVE-2023-2206). Risk of unauthorized operations or information disclosure.
|